CVE-2008-0029

CRITICAL

Cisco Application Velocity System (AVS) before 5.1.0 is installed with default passwords for some system accounts, which allows remote attackers to gain privileges.

Affects 5 products across 1 vendor.

BCS7.59
CVSS 2.010.0
EPSS2.2%
Percentile81th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-255: CWE-255
◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2008. A critical vulnerability affects Cisco systems (CVE-2008-0029). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2008-GLOBAL-331395-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2008-0029?
This vulnerability was disclosed in 2008. A critical vulnerability affects Cisco systems (CVE-2008-0029). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2008-0029?
CVE-2008-0029 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 2.2%.
Is CVE-2008-0029 actively exploited?
No confirmed active exploitation of CVE-2008-0029 as of 2026-05-30.
How do I remediate CVE-2008-0029?
Priority: MEDIUM. PSIRT: [email protected]
What systems are affected by CVE-2008-0029?
CVE-2008-0029 affects: Cisco, Cisco, Cisco, Cisco, Cisco.
Vulnerability Details
CVE IDCVE-2008-0029
BSIDBS-2008-GLOBAL-331395-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2008-01-23
Last Modified2026-04-23
ICS Relevance75%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

Cisco Application Velocity System (AVS) before 5.1.0 is installed with default passwords for some system accounts, which allows remote attackers to gain privileges.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Cisco Application Velocity System (AVS) before 5.1.0 is installed with default passwords for some system accounts, which allows remote attackers to gain privileges. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Cisco Application Velocity System 3110
Cisco Application Velocity System 3120
Cisco Application Velocity System 3180
Cisco Application Velocity System 3180A
Cisco Application Velocity System
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 6767 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashb21c974e586974fec7efeabf25166b7a663f6eaebb6f9a1204d9b469a49d1b6787ac465d963e0f9d7e69c4fdf68e793af6527308de464fc14bca4e64b50efaf8
Related CVEs affecting Cisco
CVE-2008-0529 10.0 Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, ... CVE-2003-0732 10.0 CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the gues... CVE-2003-1096 10.0 The Cisco LEAP challenge/response authentication mechanism uses passwords in ... CVE-1999-0775 10.0 Cisco Gigabit Switch routers running IOS allow remote attackers to forward un... CVE-2004-1760 10.0 The default installation of Cisco voice products, when running the IBM Direct...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →